- Angry questions in Germany after Christmas market attack
- China's Zheng pulls out of season-opening United Cup
- Minorities fear targeted attacks in post-revolution Bangladesh
- Tatum's 43-point triple-double propels Celtics over Bulls
- Tunisia women herb harvesters struggle with drought and heat
- Trump threatens to take back control of Panama Canal
- India's architecture fans guard Mumbai's Art Deco past
- Secretive game developer codes hit 'Balatro' in Canadian prairie province
- Large earthquake hits battered Vanuatu
- Beaten Fury says Usyk got 'Christmas gift' from judges
- First Singaporean golfer at Masters hopes 'not be in awe' of heroes
- Usyk beats Fury in heavyweight championship rematch
- Stellantis backtracks on plan to lay off 1,100 at US Jeep plant
- Atletico snatch late win at Barca to top La Liga
- Australian teen Konstas ready for Indian pace challenge
- Strong quake strikes off battered Vanuatu
- Tiger Woods and son Charlie share halfway lead in family event
- Bath stay out in front in Premiership as Bristol secure record win
- Mahomes shines as NFL-best Chiefs beat Texans to reach 14-1
- Suspect in deadly Christmas market attack railed against Islam, Germany
- MLB legend Henderson, career stolen base leader, dead at 65
- Albania announces shutdown of TikTok for at least a year
- Laboured Napoli take top spot in Serie A
- Schick hits four as Leverkusen close gap to Bayern on sombre weekend
- Calls for more safety measures after Croatia school stabbings
- Jesus double lifts Christmas spirits for five-star Arsenal
- Frankfurt miss chance to close on Bayern as attack victims remembered
- NBA fines Celtics coach Mazzulla and Nets center Claxton
- Banned Russian skater Valieva stars at Moscow ice gala
- Leading try scorer Maqala takes Bayonne past Vannes in Top 14
- Struggling Southampton appoint Juric as new manager
- Villa heap pain on slumping Man City as Forest soar
- Suspect in deadly Christmas market attack railed against Islam and Germany
- At least 32 die in bus accident in southeastern Brazil
- Freed activist Paul Watson vows to 'end whaling worldwide'
- Chinese ship linked to severed Baltic Sea cables sets sail
- Sorrow and fury in German town after Christmas market attack
- Guardiola vows Man City will regain confidence 'sooner or later' after another defeat
- Ukraine drone hits Russian high-rise 1,000km from frontline
- Villa beat Man City to deepen Guardiola's pain
- 'Perfect start' for ski great Vonn on World Cup return
- Germany mourns five killed, hundreds wounded in Christmas market attack
- Odermatt soars to Val Gardena downhill win
- Mbappe's adaptation period over: Real Madrid's Ancelotti
- France's most powerful nuclear reactor finally comes on stream
- Ski great Vonn finishes 14th on World Cup return
- Scholz visits site of deadly Christmas market attack
- Heavyweight foes Usyk, Fury set for titanic rematch
- Drone attack hits Russian city 1,000km from Ukraine frontier
- Former England winger Eastham dies aged 88
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.
The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.
The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."
"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."
The committee said it had asked Citizen Lab for its report "to understand their concerns better."
Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.
"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.
"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."
The flaws affect SSL certificates, which allow online entities to communicate securely.
MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.
While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."
MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.
These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.
Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.
F.Cardoso--PC